CVE-2026-95604: WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Affected Software
1 affected component
WordPress Loops & Logic<=4.2.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Loops & Logic pluginto a version that resolves this vulnerability.Fixed in 4.3.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior authentication to exploit it.
2
What security impact is indicated?
The supplied vector indicates high confidentiality impact, with no indicated integrity or availability impact. It is remotely exploitable over the network with low attack complexity and requires no user interaction.
3
Which plugin versions are affected?
Loops & Logic versions 4.2.4 and earlier are identified as affected. The provided data does not identify a fixed version or workaround.